component-vuln-intel

Fail

Audited by Snyk on Jul 31, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This document is an explicit playbook for discovering, locating, and obtaining exploit PoCs and exposed targets (FOFA/Shodan/Zoomeye) and includes guidance to bypass blocks and use proxies—instructions that clearly facilitate unauthorized compromise and exploitation.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 源自 SKILL.md 的联网情报收集流程会通过浏览器导航与 GitHub API 直接读取外部站点/社区搜索结果与 GitHub 仓库 README/代码等公开文本(例如在第2、4、6步等对第三方页面与 GitHub 内容进行抓取与解析),因此存在被外部作者提交的提示注入文本影响运行时的风险。

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 31, 2026, 01:37 AM
Issues
2
Security Audit — snyk — component-vuln-intel